Google Cloud中Apache HTTPS代理后无法访问FastAPI应用
问题
我正尝试通过HTTPS在forge-code.com域名下安全部署FastAPI应用,但遇到了问题。
已完成的操作:
- 在Google Cloud实例上部署了FastAPI应用;
- 通过实例IP地址可直接HTTPS访问该应用;
- 在Hostinger购买了域名forge-code.com并配置转发至实例;
- 通过Certbot安装了SSL证书,可通过
https://forge-code.com访问实例上的Apache2默认index.html页面。
问题:访问https://forge-code.com时,显示的是Apache2的默认index.html页面,而非我的FastAPI应用。
配置文件内容
000-default.conf
<VirtualHost *:80> ServerName forge-code.com RewriteEngine on RewriteCond %{SERVER_NAME} =forge-code.com RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent] </VirtualHost>
00-default-le-ssl.conf
<IfModule mod_ssl.c> <VirtualHost *:443> ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined ProxyPass / http://0.0.0.0:8000/ ProxyPassReverse / http://0.0.0.0:8000/ SSLEngine on ServerName forge-code.com Include /etc/letsencrypt/options-ssl-apache.conf SSLCertificateFile /etc/letsencrypt/live/forge-code.com/fullchain.pem SSLCertificateKeyFile /etc/letsencrypt/live/forge-code.com/privkey.pem </VirtualHost> </IfModule>
相关命令输出
systemctl status apache2 输出
shivajay295@instance-20240221-193932:/etc/apache2/sites-available$ systemctl status apache2 ● apache2.service - The Apache HTTP Server Loaded: loaded (/lib/systemd/system/apache2.service; enabled; preset: enabled) Active: active (running) since Fri 2024-02-23 18:37:43 UTC; 2h 30min ago Docs: https://httpd.apache.org/docs/2.4/ Process: 46449 ExecStart=/usr/sbin/apachectl start (code=exited, status=0/SUCCESS) Process: 47594 ExecReload=/usr/sbin/apachectl graceful (code=exited, status=0/SUCCESS) Main PID: 46455 (apache2) Tasks: 55 (limit: 1141) Memory: 12.5M CPU: 1.008s CGroup: /system.slice/apache2.service ├─46455 /usr/sbin/apache2 -k start ├─47598 /usr/sbin/apache2 -k start └─47599 /usr/sbin/apache2 -k start Feb 23 18:37:43 instance-20240221-193932 systemd[1]: Starting apache2.service - The Apache HTTP Server... Feb 23 18:37:43 instance-20240221-193932 systemd[1]: Started apache2.service - The Apache HTTP Server. Feb 23 20:56:01 instance-20240221-193932 systemd[1]: Reloading apache2.service - The Apache HTTP Server... Feb 23 20:56:01 instance-20240221-193932 systemd[1]: Reloaded apache2.service - The Apache HTTP Server. Feb 23 21:02:15 instance-20240221-193932 systemd[1]: Reloading apache2.service - The Apache HTTP Server... Feb 23 21:02:15 instance-20240221-193932 systemd[1]: Reloaded apache2.service - The Apache HTTP Server. shivajay295@instance-20240221-193932:/etc/apache2/sites-available$
sudo /usr/sbin/apache2ctl -S 输出
shivajay295@instance-20240221-193932:/etc/apache2/sites-available$ sudo /usr/sbin/apache2ctl -S VirtualHost configuration: *:443 forge-code.com (/etc/apache2/sites-enabled/000-default-le-ssl.conf:2) *:80 forge-code.com (/etc/apache2/sites-enabled/000-default.conf:1) ServerRoot: "/etc/apache2" Main DocumentRoot: "/var/www/html" Main ErrorLog: "/var/log/apache2/error.log" Mutex watchdog-callback: using_defaults Mutex rewrite-map: using_defaults Mutex ssl-stapling-refresh: using_defaults Mutex ssl-stapling: using_defaults Mutex proxy: using_defaults Mutex ssl-cache: using_defaults Mutex default: dir="/var/run/apache2/" mechanism=default PidFile: "/var/run/apache2/apache2.pid" Define: DUMP_VHOSTS Define: DUMP_RUN_CFG User: name="www-data" id=33 Group: name="www-data" id=33 shivajay295@instance-20240221-193932:/etc/apache2/sites-available$
补充信息
- 实例使用Ubuntu系统;
- 已确认SSL证书和密钥文件具备读取权限;
- 不清楚为何FastAPI应用无法通过forge-code.com域名提供服务,寻求解决方法以实现通过HTTPS在forge-code.com上成功部署FastAPI应用。
解决步骤
1. 启用Apache代理模块
Apache需要proxy和proxy_http模块才能转发请求到FastAPI,执行以下命令:
sudo a2enmod proxy proxy_http sudo systemctl restart apache2
2. 确认FastAPI监听地址
检查FastAPI是否绑定到0.0.0.0:8000(允许本地Apache访问):
sudo ss -tulpn | grep 8000
如果输出中没有0.0.0.0:8000,修改FastAPI启动命令,例如:
uvicorn main:app --host 0.0.0.0 --port 8000
3. 避免默认页面干扰
在00-default-le-ssl.conf的<VirtualHost *:443>块中添加空目录的DocumentRoot,覆盖全局默认路径:
DocumentRoot /var/www/empty
创建该目录并重启Apache:
sudo mkdir -p /var/www/empty sudo systemctl restart apache2
4. 排查代理错误
查看Apache错误日志,定位转发失败原因:
sudo tail -n 50 /var/log/apache2/error.log
如果出现proxy: AH00957或proxy: AH00895类错误,说明代理连接失败,需检查FastAPI是否运行、端口是否正确,或本地防火墙是否拦截请求。
5. 本地测试代理有效性
先确认FastAPI服务正常:
curl http://0.0.0.0:8000
再测试Apache代理:
curl https://forge-code.com -k
如果返回默认页面,说明虚拟主机配置未生效,需重新检查启用状态。
内容的提问来源于stack exchange,提问作者shivank anchal
相关产品推荐
相关产品推荐

